HomeSecurityUnauthorized access has already been achieved in Grok-3 AI

Unauthorized access has already been achieved on Grok-3 AI

A researcher using the pseudonym “ single mode ” has shown how client-side code manipulation can bypass access control mechanisms, allowing unauthorized access to Grok-3 AI. Grok-3 is an advanced artificial intelligence model built into Elon Musk’s X platform

See also: Amazon Redshift: Security improvements to prevent data breaches

Grok-3 AI

The exploit requires executing a custom JavaScript snippet in the browser's developer console before starting a new conversation.

The script manipulates the browser window object, looking for references to “grok-2a”—a lower-level AI model—and replacing them with “grok-3.” In doing so, it tricks the system into gaining access to the more advanced AI model.

JavaScript exploits weak security mechanisms . By focusing on how the platform assigns identifiers to AI models, the script bypasses restrictions that would normally be imposed on the server side.

See also: Alibaba Cloud vulnerability allows data upload

Once the script is executed, all subsequent API requests from the user's browser will include “grok-3” as the model identifier. This ensures access to the exclusive features offered by that model.

Unauthorized access
Unauthorized access to Grok-3 AI

This attack highlights a serious security flaw, which falls into the category of Broken Access Control — one of the most dangerous and widespread vulnerabilities in modern web applications.

Rather than implementing access restrictions directly on the server, where data is better protected, Platform X chooses to rely on client-side controls. However, this approach is inherently more vulnerable to breaches and manipulation.

This approach makes sensitive features, such as Grok-3, vulnerable to exploitation by anyone with basic technical knowledge and access to programming tools, according to Dark-Marc's post.

So far, X has not made an official statement regarding this vulnerability in the new Grok-3 AI.

See also: What is remote code execution and how to avoid it

Unauthorized access is a serious breach and can lead to significant consequences. It often involves gaining access to systems, networks, or data without proper authorization. Such actions can result in the loss of sensitive information, financial losses, and even legal consequences. It is essential that organizations and individuals implement strong cybersecurity to prevent such incidents.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS